CloudNordic and AzeroCloud lost nearly all customer data in ransomware attack

Organization
CloudNordic
Exploit
Ransomware
Industry
Cloud Hosting

Danish cloud hosting providers CloudNordic and AzeroCloud, both operating under parent company Certiqa Holding, were hit by a ransomware attack on August 18, 2023 that left most of their customers with no recoverable data.

The companies said the attackers encrypted the disks on all servers along with both the primary and secondary backup systems. CloudNordic said that despite recovery attempts it had proved impossible to restore more data, and that the majority of its customers had lost everything held with it. Websites and email systems were shut down, and the firms began rebuilding infrastructure from scratch without customer data.

According to the companies, the intrusion traced back to a data centre migration. Servers that were already infected were moved between facilities and connected to an internal network used to administer all systems, which gave the attackers a path into central administration and backup systems. CloudNordic said there was no evidence that customer data had been exfiltrated, only destroyed.

Tech Monitor reported the ransom demand at six bitcoin, roughly 157,000 US dollars at the time; TechCrunch said the amount was not specified publicly. Management said it would not pay, citing police advice and a lack of funds. Director Martin Haslund Johansson said he feared there might be no customers left once the situation was resolved, and at least one affected business owner described the consequences as unmanageable. No ransomware group publicly claimed the attack.

Sources